- Hezbollah battles troops on border as Israel pounds Lebanon
- Alcaraz, Sinner breeze into third round of Shanghai Masters
- Bagnaia wins Japan MotoGP sprint to cut Martin's lead
- Alcaraz breezes into third round of Shanghai Masters
- Gaza cultural heritage brought to light in Geneva
- 'Bullet for democracy': Trump returns to site of rally shooting
- Italy targets climate activists in 'anti-Gandhi' demo clampdown
- South Korean cult-horror series 'Hellbound' returns at BIFF
- Nepalis fear more floods as climate change melts glaciers
- Honduras arrests environmentalist's alleged murderer
- Padres pitcher Musgrove needs elbow surgery
- Supreme Court lets stand rules to curb mercury, methane emissions
- Boston beat Denver in NBA exhibition season opener, but Jokic says omens are good
- Chagos diaspora angry at lack of input on islands' fate
- Biden says 'not confident' of peaceful US election
- US trade chief defends tariff hikes when paired with investment
- Lukaku stars as Napoli beat Como to hold Serie A top spot
- Ohtani set for MLB playoff debut as Dodgers face Padres
- Pogba's drug ban cut to 18 months from four years
- Devine leads New Zealand to big win over India in Women's T20 World Cup
- Bosnia floods kill 16 people
- EU court blocks French ban on vegetable 'steak' labelling
- Prosecutors seek dismissal of rape charges against French rugby players
- Meta AI turns pictures into videos with sound
- Bolivia's Morales says claims he raped a minor are a 'lie'
- MLB Reds hire two-time champion Francona as manager
- Daniel Maldini receives first Italy call-up for Nations League
- US dockworkers return to ports after three-day strike
- Ancelotti points finger at Madrid's 'lack of intensity'
- Haiti reeling after 70 killed in gang attack
- Five Czech kids in hospital over TikTok 'piercing challenge'
- What happens next in Iran-Israel conflict?
- Country star Garth Brooks denies rape accusations
- Stubbs hits maiden century as South Africa make 343-4 against Ireland
- DR Congo to begin mpox vaccination campaign Saturday in east
- Odegaard injury has forced Arsenal to be 'different', says Arteta
- Ratcliffe refuses to guarantee Ten Hag's Man Utd future
- Meta must limit data use for targeted ads: EU court
- Mauritius to hold legislative election on November 10
- Britain qualify for America's Cup final after 60-year wait
- IMF asks Sri Lanka to protect hard-won gains
- Morata returns to Spain Nations League squad after injury
- Irish regulator to probe Ryanair use of facial recognition
- Public allowed to see video evidence in France mass rape trial
- US hiring soars past expectations in sign of resilient market
- Under-fire Ten Hag 'together' with Man Utd hierarchy
- Guardiola talks of Man City love affair as financial hearing rumbles on
- De Bruyne out of Belgium Nations League squad
- Japanese trainer Yahagi hopes Shin Emperor achieves 50-year-old Arc dream
- UK's Starmer hails 'landmark' carbon capture funding
Mandatory Chinese Olympics app has 'devastating' encryption flaw: analyst
An app all attendees of the upcoming Beijing Olympics must use has encryption flaws that could allow personal information to leak, a cyber security watchdog said Tuesday.
The "simple but devastating flaw" in the encryption of the MY2022 app, which is used to monitor Covid and is mandatory for athletes, journalists and other attendees of the games in China's capital, could allow health information, voice messages and other data to leak, warned Jeffrey Knockel, author of the report for Citizen Lab.
The International Olympic Committee responded to the report by saying users can disable the app's access to parts of their phones and that assessments from two unnamed cyber security organizations "confirmed that there are no critical vulnerabilities."
"The user is in control over what the... app can access on their device," the committee told AFP, adding that installing it on cellphones isn't required "as accredited personnel can log on to the health monitoring system on the web page instead."
The committee said it had asked Citizen Lab for its report "to understand their concerns better."
Citizen Lab said it notified the Chinese organizing committee for the Games of the issues in early December and gave them 15 days to respond and 45 days to fix the problem, but received no reply.
"China has a history of undermining encryption technology to perform political censorship and surveillance," Knockel wrote.
"As such, it is reasonable to ask whether the encryption in this app was intentionally sabotaged for surveillance purposes or whether the defect was born of developer negligence," he continued, adding that "the case for the Chinese government sabotaging MY2022's encryption is problematic."
The flaws affect SSL certificates, which allow online entities to communicate securely.
MY2022 doesn't authenticate SSL certificates, meaning other parties could access the app's data, while data is transmitted without the usual encryption SSL certificates have, Knockel wrote.
While the app is transparent about the medical information it collects as part of China's efforts to screen Covid-19 cases, he said "it is unclear with whom or which organization(s) it shares this information."
MY2022 also contains a list called "illegalwords.txt" of "politically sensitive" phrases in China, many of which relate to China's political situation or its Tibetan and Uighur Muslim minorities.
These include keywords like "CCP evil" and Xi Jinping, China's president, though Knockel said it was unclear if the list was being actively used for censorship purposes.
Because of these features, the app may violate both Google and Apple policies around smartphone software, and "also China's own laws and national standards pertaining to privacy protection, providing potential avenues for future redress," he wrote.
F.Cardoso--PC